[Adium-devl] Padlocks & Security
Colin Barrett
timber at lava.net
Thu Oct 18 03:38:54 UTC 2007
On Oct 17, 2007, at 8:30 PM, Evan Schoenberg wrote:
>
> On Oct 17, 2007, at 11:25 PM, Colin Barrett wrote:
>
>> On Oct 17, 2007, at 8:21 PM, Peter Hosey wrote:
>>
>>> On Oct 17, 2007, at 20:00:53, Colin Barrett wrote:
>>>> Is showing this SSL information useful? Can it be inferred from
>>>> prefs? If we do want this information to be in UI, how do we
>>>> display it in a way that doesn't confuse people, and doesn't give
>>>> users the wrong impression.
>>>
>>> What if we use the certificate icon instead to mean “SSL”?
>>
>> Not a bad idea. Could we get a UI hooked up to show information about
>> the certificate if it was clicked (and maybe a rollover state as
>> well?)
>
> It's worth pointing out, in response, that libpurple HEAD (which we're
> using in trunk) has support for SSL certificate verification/
> validation/details, but only if using GnuTLS for SSL. We're currently
> using OpenSSL, which ships with OS X.
Does using GnuTLS have any other advantages? (Shipping it means a
codesize hit)
Would it be possible to do add cert validation code for OpenSSL as well?
-Colin
More information about the devel
mailing list